Tagged “exploit-available”
CVEs tagged exploit-available, newest first.
3555 CVEsRSS
CVE-2026-28498High· 7.5PoCAuthlib is a Python library which builds OAuth and OpenID Connect servers
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. S…
CVE-2026-27962Critical· 9.1PoCAuthlib is a Python library which builds OAuth and OpenID Connect servers
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attacker to forge arbitrary JWT tokens that…
CVE-2026-3227Medium· 6.8PoCA command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command
A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command. In the router configuration import function allows an au…
CVE-2026-31899High· 7.5PoCCairoSVG vulnerable to Exponential DoS via recursive <use> element amplification
CairoSVG vulnerable to Exponential DoS via recursive <use> element amplification
CVE-2026-32597High· 7.5PoCPyJWT is a JSON Web Token implementation in Python
PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not …
CVE-2026-32247High· 8.1PoCGraphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
CVE-2026-3783Medium· 5.3PoCWhen an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances. If the hostname that the first request is re…
When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances. If the hostname that the first request is re…
CVE-2026-3805High· 7.5PoCWhen doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.
When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.
CVE-2026-23813Critical· 9.8PoCA vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls
A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable res…
CVE-2026-31844High· 8.8PoCAn authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the displayby parameter used by the GetDistinctValues functiona…
An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the displayby parameter used by the GetDistinctValues functiona…
CVE-2026-31900Critical· 9.8PoCBlack is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, us…
Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject: true, for reading the version of Black to use from the repository pyproject.toml. A mal…
CVE-2025-70330Low· 3.3PoCEasy Grade Pro 4.1.0.2 contains a file parsing logic flaw in the handling of proprietary .EGP gradebook files
Easy Grade Pro 4.1.0.2 contains a file parsing logic flaw in the handling of proprietary .EGP gradebook files. By modifying specific fields at precise offsets within an otherwise valid .EGP file, an attacker can trigger an out-of-bounds …
CVE-2025-67038Critical· 9.8CISA KEVPoCAn issue was discovered in Lantronix EDS5000 2.1.0.0R3
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This al…
CVE-2026-23907Medium· 5.3PoCThis issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6. The ExtractEmbeddedFiles example contains a path traversal vulnerability (CWE-22) because the filename that i…
This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6. The ExtractEmbeddedFiles example contains a path traversal vulnerability (CWE-22) because the filename that i…
CVE-2026-27280High· 7.8PoCDNG SDK versions 1.7.1 2471 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user
DNG SDK versions 1.7.1 2471 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…
CVE-2026-26118High· 8.8PoCAzure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network
Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network
CVE-2026-27826High· 8.2PoCMCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers
MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers
CVE-2026-24294High· 7.8PoCImproper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
CVE-2026-0846High· 8.6PoCArbitrary File Read via Absolute Path Input in nltk.util.filestring()
A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without saniti…
CVE-2026-30928HighPoCGlances Exposes Unauthenticated Configuration Secrets
Glances Exposes Unauthenticated Configuration Secrets
CVE-2025-69219High· 8.8PoCApache Airflow Providers Http has Unsafe Pickle Deserializatio leading to RCE via HttpOperator
Apache Airflow Providers Http has Unsafe Pickle Deserializatio leading to RCE via HttpOperator
CVE-2026-25604Medium· 5.4PoCIn AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access co…
In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access co…
CVE-2024-14027Medium· 5.5PoCIn the Linux kernel, the following vulnerability has been resolved: fs/xattr: missing fdput() in fremovexattr error path In the Linux kernel, the fremovexattr() syscall calls fdget() to acquire a file reference but returns early withou…
In the Linux kernel, the following vulnerability has been resolved: fs/xattr: missing fdput() in fremovexattr error path In the Linux kernel, the fremovexattr() syscall calls fdget() to acquire a file reference but returns early withou…
CVE-2026-29786Medium· 6.3PoCnode-tar is a full-featured Tar for Node.js
node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables f…
CVE-2026-29780Medium· 5.5PoCeml_parser: Path Traversal in Official Example Script Leads to Arbitrary File Write
eml_parser: Path Traversal in Official Example Script Leads to Arbitrary File Write
CVE-2026-0847High· 8.6PoCPath Traversal in nltk/nltk
A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCorpusReader, and BracketParseCorpusReader. These classes fa…
CVE-2026-23231High· 7.8PoCnetfilter: nf_tables: fix use-after-free in nf_tables_addchain()
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tables_addchain() nf_tables_addchain() publishes the chain to table->chains via list_add_tail_rcu() (in nft_chain_add())…
CVE-2025-66024Critical· 9.0PoCThe XWiki blog application allows users of the XWiki platform to create and manage blog posts
The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9.15 and prior to 9.15.7 are vulnerable to Stored Cross-Site Scripting (XSS) via the Blog Post Title. The vulnerability…
CVE-2026-20079Critical· 10.0CISA KEVPoCA vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access …
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access …
CVE-2026-0014Medium· 6.2PoCIn isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation
In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interactio…